Duplicate SIM and banking lapses lead to ₹1.5 crore payout in cyber fraud case

0
25
Duplicate SIM and banking lapses lead to ₹1.5 crore payout in cyber fraud case
Duplicate SIM and banking lapses lead to ₹1.5 crore payout in cyber fraud case

A nearly 11-year-old cyber fraud case involving a duplicate SIM and 13 unauthorised RTGS transactions has resulted in the Bank of India and a telecom operator being held responsible for security lapses.

An adjudicating authority under the Information Technology Act, 2000, has directed Bank of India to pay Pune-based audit firm G D Apte & Co ₹64.44 lakh in compensation, along with 12% annual interest. With interest, the payout is expected to reach around ₹1.5 crore.

The authority has also ordered former Idea Cellular Ltd, now Vodafone Idea Ltd, to pay ₹5 lakh for issuing a duplicate SIM connected to the firm’s internet banking facility without adequate verification. Both payments must be made within 30 days.

The case relates to 13 allegedly unauthorised RTGS transactions carried out on March 11, 2015, from the firm’s current and overdraft accounts at Bank of India’s Jangli Maharaj Road branch in Pune. One transaction was worth ₹6.6 lakh, while 12 transactions from the overdraft account totalled ₹78.93 lakh. Around ₹14 lakh was recovered after the fraud was discovered.

The firm said its registered mobile number stopped functioning on March 10, 2015, following which a duplicate SIM was issued without its authorisation. The number was linked to the bank account for receiving transaction alerts and one-time passwords.

The authority found major gaps in the bank’s internal controls. Under the agreed Maker-Checker process, transactions had to be initiated by a lower-level user and approved by at least 2 of 3 senior authorised users. The accounts also had a cumulative monthly RTGS limit of ₹50 lakh.

However, 12 transactions totalling ₹78.93 lakh were processed from the overdraft account. The authority said the records did not establish that the required approval process had been followed and that the bank could not satisfactorily explain how transactions exceeding the prescribed limit were permitted.

Bank of India was therefore held primarily liable for the loss.

The authority also found that Idea Cellular had failed to adequately verify the applicant’s authorisation, identity details, company letterhead and stamp before issuing the duplicate SIM. However, its liability was treated as contributory because it did not directly initiate or process the banking transactions.

Bank of India denied negligence, while Idea Cellular said the SIM was obtained by an individual posing as the firm’s authorised representative using documents that appeared valid.

Cybersecurity expert and former IPS officer Prof. Triveni Singh said the case shows that cyber security extends beyond bank systems and passwords. Mobile numbers, SIM issuance and customer verification are also critical parts of the security chain. Weaknesses at these levels, combined with ineffective banking controls, can create opportunities for unauthorised access and fund transfers.

The ruling places primary responsibility on the bank for failing to enforce its authorisation and transaction-limit controls, while the telecom operator was held contributorially responsible for the SIM verification lapse.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.